PT-2026-23122 · Idc · Sfx2100 Satellite Receiver
Abdul Mhanni
·
Published
2026-03-05
·
Updated
2026-03-11
·
CVE-2026-29126
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H/AU:N/R:U |
Name of the Vulnerable Software and Affected Versions
IDC SFX2100 Satellite Receiver (affected versions not specified)
Description
A misconfiguration involving incorrect permission assignment of a world-writable file, specifically
/etc/udhcpc/default.script, exists. This allows a local, unprivileged attacker to potentially execute arbitrary commands with root privileges. The issue stems from the modification of a root-owned, world-writable BusyBox udhcpc DHCP event script. This script is executed during DHCP lease events – obtaining, renewing, or losing a lease – leading to potential local privilege escalation and persistence.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Incorrect Authorization
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sfx2100 Satellite Receiver